WebsiteBaker Logo
  • *
  • Templates
  • Help
  • Add-ons
  • Download
  • Home
*
Welcome, Guest. Please login or register.

Login with username, password and session length
 

News


WebsiteBaker 2.13.6 is now available!


Will it continue with WB? It goes on! | Geht es mit WB weiter? Es geht weiter!
https://forum.websitebaker.org/index.php/topic,32340.msg226702.html#msg226702


The forum email address board@websitebaker.org is working again
https://forum.websitebaker.org/index.php/topic,32358.0.html


R.I.P Dietmar (luisehahne) and thank you for all your valuable work for WB
https://forum.websitebaker.org/index.php/topic,32355.0.html


* Support WebsiteBaker

Your donations will help to:

  • Pay for our dedicated server
  • Pay for domain registration
  • and much more!

You can donate by clicking on the button below.


  • Home
  • Help
  • Search
  • Login
  • Register

  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • Security Announcements »
  • Security Patch for WB 2.8.0 available
  • Print
Pages: [1]   Go Down

Author Topic: Security Patch for WB 2.8.0 available  (Read 27673 times)

susigross

  • Guest
Security Patch for WB 2.8.0 available
« on: October 06, 2009, 08:01:56 PM »
A Security related bug has been found in the WebsiteBaker CMS.

Affected systems
    * Only WebsiteBaker version 2.8.0
    * Only installations which have enabled the options to sign in or to change user settings in the frontend

Vulnerability Impact
    * Spamming, annoying and impersonating registered users
    * To protect still unpatched systems, no further details will be published during the next 3 months

Maximum Severity Rating
    * High (for systems matching all of the conditions under the Affected Systems section)
    * None (for all other systems)

Instructions how to patch
  • Just download the patched file attached to this message
  • Unzip this file
  • Replace the file /framework/class.wb.php with the patched version by ftp

Acknowledgements
We want to thank the users Chio, Thorn and Stefek for reporting this bug in an appropriate manner.

Frank Heyne (WebsiteBaker Security Team)


[gelöscht durch Administrator]
Logged

Offline kweitzel

  • WebsiteBaker Org e.V.
  • **
  • Posts: 6983
  • Gender: Male
Re: Security Patch for WB 2.8.0 available
« Reply #1 on: October 07, 2009, 12:43:34 AM »
Dear all,

there was a misconfiguration in the board which prevented everybody from seeing the attachment. This has been changed now, the attachment should be available to every member and visitor of this forum now!

cheers

Klaus
Logged

  • Print
Pages: [1]   Go Up
  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • Security Announcements »
  • Security Patch for WB 2.8.0 available
 

  • SMF 2.0.19 | SMF © 2017, Simple Machines
  • XHTML
  • RSS
  • WAP2